Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5343

Опубликовано: 15 дек. 2015
Источник: redhat
CVSS2: 4.6

Описание

Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5subversionNot affected
Red Hat Enterprise Linux 6subversionNot affected
Red Hat Enterprise Linux 7subversionWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-122
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1289959subversion: (mod_dav_svn) integer overflow when parsing skel-encoded request bodies

4.6 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.6
ubuntu
почти 10 лет назад

Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.

CVSS3: 7.6
nvd
почти 10 лет назад

Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.

CVSS3: 7.6
debian
почти 10 лет назад

Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, ...

suse-cvrf
около 10 лет назад

Security update for subversion

CVSS3: 7.6
github
больше 3 лет назад

Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.

4.6 Medium

CVSS2